BugTraq
[Kurdish Security # 9] MyMail Directory Traversal And XSS Attacking Vulnerability Jun 26 2006 01:20PM
botan linuxmail org
# Kurdish Security Advisory

# irc.gigachat.net #kurdhack

# Discovered by Botan

# http://scripts.codingclick.com/MyMail/

http://kurdishsecurity.blogspot.com/2006/06/kurdish-security-9-mymail-di
rectory.html

CodingClick.com MyMail Script is useing for scripts.The passing can do between directory. Examine..

Now only first Directory Traversal vuln

Vulnerable Version = 0.x

http://www.site.com/[MyMail_path]/admin/

http://www.site.com/[MyMail_path]/admin/list.php?action=add

http://www.site.com/[MyMail_path]/admin/email.php?action=add or /delete

http://www.site.com/[MyMail_path]/admin/export.php

http://www.site.com/[MyMail_path]/admin/archive.php?Action=add or /delete

Now XSS attacking looking

Vulnerable Version = 1.0 Beta

http://www.site.com/[MyMail_path]/admin/login.php=error=[XSS]

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus